mediumCVSS 6.5Vulnerability

GHSA-6jm4-83g2-35gv

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-72fw-cqh5-f324. This link is maintained to preserve external references. ## Original DescriptionOpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session.

Properties

ghsa_id
GHSA-6jm4-83g2-35gv
severity
medium
summary
Duplicate Advisory: memory-wiki shared search could miss session visibility checks
cvss_score
6.5
cve_id
GHSA-6jm4-83g2-35gv
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-06-16T21:31:57Z
source_url
https://github.com/advisories/GHSA-6jm4-83g2-35gv
ghsa_updated
2026-06-18T20:31:27Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/openclaw

AFFECTS (1)

[Software]npm/openclaw

Explore deeper with Ninja Signal's threat intelligence graph